Atlas Knowledge Base
Dashboard
TURN Server

TURN Server

The SBN Media TURN server - relays video through firewalls so SBN Video connects on restrictive networks.

configuration
firewall
sbn-media
turn-server
turnserver
video
webrtc

TURN Server

The TURN server relays video through firewalls so SBN Video can connect on networks where a direct connection is not possible. It is built into SBN Media and is on by default.

Overview

When a client opens a video stream, SBN Video first tries to connect directly. On restrictive networks a direct path cannot be made, and the video is relayed through a TURN server instead. Because SBN Media includes its own TURN server, this works in most networks without any separate relay software such as coturn.

The TURN server gives each client short-lived credentials automatically while the video session is being set up. You do not normally configure per-client credentials yourself.

  1. Runs: When configured; at most one per host. It is on by default on a host that serves video.
  2. Required: Required for video to reach clients across firewalls and NAT. If you choose to use an external TURN server instead, you can turn the built-in one off.
  3. Depends on: NATS, and being reachable from clients on its control and media ports.

Because clients connect to the TURN server directly, it should sit in the DMZ, alongside the API Proxy.

Configuration

The TURN server is configured under the turnserver namespace. View the defaults with ./sbn-media config eject and set host-specific overrides in sbn-media.local.yaml.

The built-in TURN server is on by default. To use an external TURN server instead, set webrtcpeer.disableInternalTurnServer to true and point WebRTC at the external server.


Setting

Default

Description

turnserver.port

3478

The control port clients connect to.

turnserver.address

0.0.0.0

The address to bind to.

turnserver.publishedURL

empty

The address advertised to clients. Defaults to the bind address and port. Set this when the host's public address differs from the address it binds to, so clients are given an address they can actually reach.

turnserver.packet.minPort

1024

The lowest port used to relay media.

turnserver.packet.maxPort

65535

The highest port used to relay media.

turnserver.authorizationTimeoutInSeconds

10

How long a client has to authorize before the attempt times out.

turnserver.credentials

empty

Optional fixed username and password per realm, for external or manual use. The built-in server issues per-session credentials automatically and does not need these.

Example:

turnserver:
port: 3478

# Advertise an address clients can reach, if it differs from the bind address.
publishedURL: "turn:your-host:3478"

# The range of ports used to relay media.
packet:
minPort: 1024
maxPort: 65535

For the TURN server to work across a firewall, the control port (3478 by default) and the media relay range must be reachable from clients, and turnserver.publishedURL must advertise an address clients can reach. Because it is contacted directly by clients, the TURN server should sit in the DMZ, alongside the API Proxy.

After changing these settings in sbn-media.local.yaml, reload the configuration for them to take effect. Changing the port or the relay range requires restarting the service.

Firewall

Because the TURN server is exposed in the DMZ, it enforces the built-in SBN Media firewall on the clients that connect to it: it checks the source address of each client and rejects any that the firewall does not allow. The firewall is configured under the separate firewall namespace and is off by default. When enabled it can allow or reject by IP address and by country (using a built-in IP-location database). The same firewall is shared by the other externally-facing SBN Media services.

firewall:
enabled: true
country:
# If an allow list is given, only these countries are permitted.
allow:
- dk
- gb

FAQ

Do I need to install coturn or another TURN server?

No. SBN Media's own TURN server is built in and on by default, and it handles firewall traversal for most networks. Install an external TURN server only if you have a specific reason to, and then turn the built-in one off with webrtcpeer.disableInternalTurnServer.

Video works on the local network but not remotely. What should I check?

Confirm the control port (3478) and the media relay range are open to clients, and that turnserver.publishedURL advertises an address clients can reach - this is the most common cause when the host's public address differs from the address it binds to. If the service will not start, run it in the foreground with sbn-media service exec turnserver -ld to see the error.

How are the TURN credentials managed?

The TURN server issues short-lived credentials to each client automatically as the video session is set up, so there is normally nothing to configure. The turnserver.credentials list is only for fixed credentials used by an external or manual setup.

Can I use an external TURN server instead?

Yes. Set webrtcpeer.disableInternalTurnServer to true and provide the external server's address and credentials in the WebRTC configuration. The built-in TURN server then does not run.

Related pages

  1. SBN Media Overview (SBN-Media/overview)
  2. Installing and Configuring SBN Media (SBN-Media/installation)
  3. API Proxy (SBN-Media/Platform/api-proxy)
  4. Firewall (SBN-Media/Configuration/firewall)




Was this helpful?